← Back

CVE-2025-8591

nvd nist
Published: Jul 6, 2026Modified: Jul 9, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: ed10eef1-636d-4fbe-9993-6890dfa878f8 (Secondary)

Description

The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.

Affected (23)

8 products
Api Control Plane
Api Manager
Identity Server
Identity Server As Key Manager
Open Banking Am
Open Banking Iam
Traffic Manager
Universal Gateway
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.44
From 4.6.0 to 4.6.0.8
Configuration B
10 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 3.1.0 to 3.1.0.355
From 3.2.0 to 3.2.0.459
From 3.2.1 to 3.2.1.78
From 4.0.0 to 4.0.0.380
From 4.1.0 to 4.1.0.243
From 4.2.0 to 4.2.0.183
From 4.3.0 to 4.3.0.94
From 4.4.0 to 4.4.0.58
From 4.5.0 to 4.5.0.43
From 4.6.0 to 4.6.0.7
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 5.10.0 to 5.10.0.384
From 6.0.0 to 6.0.0.255
From 7.0.0 to 7.0.0.131
From 7.1.0 to 7.1.0.51
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
From 5.10.0 to 5.10.0.375
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.0.0.404
From 2.0.0 to 2.0.0.424
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.42
From 4.6.0 to 4.6.0.7
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Wso2
From 4.5.0 to 4.5.0.42
From 4.6.0 to 4.6.0.7

References (1)

Timeline

No history available yet.